GhostNet Update

Starting on March 30 2009 the GhostNet starting coming down. The attacker began removing the files and directories being used and then began to configure the domain names of some the control servers to point to 127.0.0.1. Files hosted on other (probably compromised) “command” servers also started disappearing at the same time. It’ll be interesting to see if, when and where the network pops up again.